Vulnerabilities > Cisco > IOS > 12.1

DATE CVE VULNERABILITY TITLE RISK
2007-08-09 CVE-2007-4291 Voice vulnerability in Cisco IOS and Unified Communications Manager
Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service via (1) a malformed MGCP packet, which causes a device hang, aka CSCsf08998; a malformed H.323 packet, which causes a device crash, as identified by (2) CSCsi60004 with Proxy Unregistration and (3) CSCsg70474; and a malformed Real-time Transport Protocol (RTP) packet, which causes a device crash, as identified by (4) CSCse68138, related to VOIP RTP Lib, and (5) CSCse05642, related to I/O memory corruption.
network
cisco
7.1
2007-08-09 CVE-2007-4286 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco IOS
Buffer overflow in the Next Hop Resolution Protocol (NHRP) functionality in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (restart) and execute arbitrary code via a crafted NHRP packet.
network
cisco CWE-119
critical
9.3
2007-08-09 CVE-2007-4285 Denial-Of-Service vulnerability in IOS
Unspecified vulnerability in Cisco IOS and Cisco IOS XR 12.x up to 12.3, including some versions before 12.3(15) and 12.3(14)T, allows remote attackers to obtain sensitive information (partial packet contents) or cause a denial of service (router or component crash) via crafted IPv6 packets with a Type 0 routing header.
network
low complexity
cisco
critical
9.0
2007-05-16 CVE-2007-2688 Unspecified vulnerability in Cisco IOS and IPS Sensor Software
The Cisco Intrusion Prevention System (IPS) and IOS with Firewall/IPS Feature Set do not properly handle certain full-width and half-width Unicode character encodings, which might allow remote attackers to evade detection of HTTP traffic.
network
low complexity
cisco
7.8
2007-05-10 CVE-2007-2587 Multiple vulnerability in Cisco IOS FTP Server
The IOS FTP Server in Cisco IOS 11.3 through 12.4 allows remote authenticated users to cause a denial of service (IOS reload) via unspecified vectors involving transferring files (aka bug ID CSCse29244).
network
cisco
6.3
2007-01-11 CVE-2007-0199 Denial Of Service vulnerability in Cisco IOS Data-link Switching
The Data-link Switching (DLSw) feature in Cisco IOS 11.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via "an invalid value in a DLSw message...
network
low complexity
cisco
5.0
2006-09-23 CVE-2006-4950 Unspecified vulnerability in Cisco IOS
Cisco IOS 12.2 through 12.4 before 20060920, as used by Cisco IAD2430, IAD2431, and IAD2432 Integrated Access Devices, the VG224 Analog Phone Gateway, and the MWR 1900 and 1941 Mobile Wireless Edge Routers, is incorrectly identified as supporting DOCSIS, which allows remote attackers to gain read-write access via a hard-coded cable-docsis community string and read or modify arbitrary SNMP variables.
network
low complexity
cisco
critical
10.0
2006-09-09 CVE-2006-4650 Remote Security vulnerability in IOS 12.0/12.1/12.2
Cisco IOS 12.0, 12.1, and 12.2, when GRE IP tunneling is used and the RFC2784 compliance fixes are missing, does not verify the offset field of a GRE packet during decapsulation, which leads to an integer overflow that references data from incorrect memory locations, which allows remote attackers to inject crafted packets into the routing queue, possibly bypassing intended router ACLs.
network
high complexity
cisco
2.6
2006-02-01 CVE-2006-0485 Unspecified vulnerability in Cisco IOS
The TCL shell in Cisco IOS 12.2(14)S before 12.2(14)S16, 12.2(18)S before 12.2(18)S11, and certain other releases before 25 January 2006 does not perform Authentication, Authorization, and Accounting (AAA) command authorization checks, which may allow local users to execute IOS EXEC commands that were prohibited via the AAA configuration, aka Bug ID CSCeh73049.
local
low complexity
cisco
4.6
2006-01-21 CVE-2006-0340 Improper Input Validation vulnerability in Cisco IOS
Unspecified vulnerability in Stack Group Bidding Protocol (SGBP) support in Cisco IOS 12.0 through 12.4 running on various Cisco products, when SGBP is enabled, allows remote attackers on the local network to cause a denial of service (device hang and network traffic loss) via a crafted UDP packet to port 9900.
network
cisco CWE-20
7.1